API Document Format Conversion Vulnerability in Gotenberg by Gotena
CVE-2026-35458

8.7HIGH

Key Information:

Vendor

Gotenberg

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35458?

Gotenberg, an API designed for converting different document formats, has a vulnerability present in versions 8.29.1 and earlier. This vulnerability arises from the use of the dlclark/regexp2 library, which compiles user-defined scope patterns without a proper timeout management. As a result, users who access specific features reliant on this logic can potentially cause the application's workers to hang, leading to denial of service. This issue emphasizes the importance of implementing rigorous timeout controls in APIs to protect against resource exhaustion.

Affected Version(s)

gotenberg <= 8.29.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.